Microsoft Defender Administrator
Summary
Administers Microsoft Defender security tools for a DoD customer, monitoring threats, managing antivirus, and ensuring cross-platform protection while following strict compliance procedures.
This position is full time remote and requires the candidate hold an active secret clearance.
Are you detail-oriented and passionate about cybersecurity? We’re searching for a Microsoft Defender Operator to join our dynamic team and ensure the smooth, day-to-day operation of our Microsoft Defender services for our Department of Defense (DOD) customer. If you’re committed to maintaining high security standards and eager to contribute to a critical mission, this could be the perfect opportunity for you!
Responsibilities:
1. Monitoring Endpoint Detection and Response (EDR):
• Continuously monitor EDR solutions to detect and report threats to the Security Operations Center (SOC) in real-time.
2. Managing Next-Generation Antivirus (NGAV):
• Ensure NGAV solutions are running optimally and address any alerts or issues.
• Perform routine checks and updates to maintain peak performance.
3. Maintaining Attack Surface Reduction:
• Ensure rules and controls are in place to minimize the attack surface of endpoints, as provided by the SOC
• Report any deviations or issues to the engineering team for review.
4. Integrating Cloud-Delivered Protection:
• Verify that real-time updates and threat intelligence from the Microsoft cloud are being received and applied.
• Report any discrepancies or issues to the engineering team.
5. Connecting with SIEM Solutions:
• Ensure seamless integration of Microsoft Defender with Microsoft Sentinel and other SIEM tools.
• Monitor and maintain centralized logging, analytics, and reporting dashboards.
• Perform data analysis via the SIEM tool as required.
6. Ensuring Cross-Platform Protection:
• Verify comprehensive security across Windows, Linux, and mobile devices.
• Report any platform-specific issues to the engineering team.
7. Delivering Comprehensive Reporting and Analytics:
• Generate and review detailed reports on security posture, incidents, and compliance.
• Ensure dashboards and alerts are functioning correctly and report any issues.
8. Applying Prescribed Procedures:
• Follow established procedures and guidelines for maintaining Microsoft Defender solutions.
• Escalate any issues or anomalies to the engineering team.
9. Implementing Windows Defender Application Control (WDAC):
• Ensure WDAC policies are correctly applied and functioning as intended.
• Report any policy violations or issues to the engineering team.
10. Integrating Microsoft Defender, Intune, and Purview for Data Loss Prevention (DLP):
• Ensure DLP policies are correctly implemented and functioning across endpoints, mobile devices, and cloud services.
• Implement approved DLP waivers for authorized users and devices.
• Monitor DLP incidents and report any policy violations or data exfiltration attempts to the engineering team.
• Maintain unified reporting and alerts for any DLP-related issues.